Who we are
Rauta is operated today by [[TO BE CONFIRMED: the data controller's legal name and address — a registered company (e.g. Rauta Fit OÜ) if one exists by the time you read this, otherwise the individual operator's own legal name and contact address]]. If a company is formed to operate Rauta later, this section will name it as the controller instead — the underlying commitments on this page do not change either way.
"We", "us", and Rauta mean whoever is named above, acting as the data controller for the personal data described on this page.
What we collect, and why
Account information
Your email address, so you can sign in and so we can reach you about your account. We use a passwordless "magic link" sign-in: when you request one, we store a securely hashed (never plain-text) version of the code or link, plus the IP address the request came from, purely to let you sign in and to stop abuse of that request. The code or link itself stops working within minutes, whether or not you use it — after that it's a dead credential, not a live one. We keep that hashed record and the IP address for 30 days from when it was created. A daily automated process then permanently deletes it — so in practice it is fully gone within 31 days of creation, never longer — whether or not you ever used it, and regardless of whether your account is still open. This is a routine, scheduled deletion, not something you need to ask for. These records are also removed in full immediately if you delete your account before that 30-day window ends (see "Deleting your account" below).
Profile
An optional display name, and your timezone (so your training dates line up with your own calendar day, including when you travel).
The sign-up form also asks for your name and your preferred units (kilograms or pounds). Both are stored on our server, against your account, so they follow you to a new device.
Separately, and only if you turn on health-data consent, you can record body measurements — bodyweight, height, and a self-described build. These are treated as health-adjacent data under the same consent as the pain and wellbeing fields described below, and none of them is ever required. They are stored as dated measurements rather than as a single current value, so a change over time is visible to you rather than overwritten.
That consent is enforced by the database itself, not only by the app: a measurement cannot be written without a live, unwithdrawn health-data consent on your account, and withdrawing it deletes every measurement already stored. A body-mass index is calculated from bodyweight and height when you have given both, and is never stored — it is worked out fresh each time it is shown, and always shown with the caveat that it does not distinguish muscle from anything else.
Training history
Which programme you're enrolled in and when; the date and time of each training session; and, for each set you log — the exercise, the weight you actually lifted, reps, the RPE you reported, any free-text notes you add, when the set started and finished, and when the record reached our server.
If you fill in the optional warm-up log, the minutes, the distance, the heart rate and which machine you used for that warm-up block. All four are optional and independent — leaving any of them blank records nothing for it, never a zero and never a guessed machine. The machine is one of four fixed choices, never free text. The heart rate is treated as health-adjacent data, described below; the minutes, distance and machine are ordinary training numbers.
Benchmark measurements
Mobility and capability benchmarks you log — for example a hip-rotation or shoulder-mobility measurement, or a conditioning-test result.
Bounced or complained-about emails
If an email we send you bounces or is reported as spam, we keep your email address and the reason on a suppression list, so we stop emailing an address that doesn't want or can't receive mail from us. Unlike everything else on this page, this record is tied to the email address itself, not to your account — it is a genuine exception to the deletion described below, and it exists to protect that address from unwanted mail even after an account tied to it is gone.
We do not collect your name beyond an optional display name, your payment details (we don't take payment today — see the Terms of service), or any data beyond what's described on this page.
Why we can process it
Your account information, profile, training history, and benchmark data are processed because they are necessary to provide the service you signed up for — running your training log and showing it back to you (GDPR Article 6(1)(b), contract necessity).
The IP address recorded at sign-in is processed on the basis of our legitimate interest in keeping accounts secure and preventing abuse of the sign-in system (Article 6(1)(f)).
The health-adjacent fields described next are processed on a different, stricter basis — see below.
Health-adjacent data
Some of what you can log is health-adjacent: a per-set pain flag; the subjective wellbeing ratings you record about a session — how you arrived that day, how you slept, and your own rating of how hard the whole session felt; a warm-up heart rate, if you enter one; and the mobility and movement-screen measurements a session asks you to take, such as a hip-rotation rating or an overhead-reach height. We treat all of these as special category data under GDPR Article 9, not ordinary training numbers, because they describe your body and how it's responding, not just what you lifted.
We only process these fields on the basis of your explicit, separate consent (Article 9(2)(a)), captured through its own checkbox at signup — deliberately distinct from your general acceptance of these Terms and this Privacy policy, not bundled into it. Recording pain and wellbeing data is optional: declining this consent does not stop you from using the rest ofRauta, it only means those specific fields are not collected from you.
You can withdraw this consent at any time (see "Your rights" below). Withdrawing it stops us collecting new pain and wellbeing entries going forward; it does not undo processing that already happened before you withdrew. If you also want existing entries erased, use the deletion or rectification paths described below.
Nobody at Rauta monitors these entries in real time or reaches out based on them — see the Medical disclaimer for what that means in practice, including what to do if you're actually in pain.
AI-generated summaries (Anthropic)
If you use a session or weekly AI-generated summary, your relevant training history for that period — the exercises, sets, reps, RPE, notes, and any pain or wellbeing entries you've logged for it — is sent to Anthropic, the company that operates the Claude models, so it can generate the written summary. This can include the health-adjacent fields described above.
We are stating this plainly because it's a real, meaningful data flow, not a footnote: your training data — potentially including sensitive fields — leaves Rauta's own systems and is processed by a third party to generate that summary. This only happens for the summary feature specifically, and only for the data relevant to the summary you asked for, not your whole account history at once.
Who else sees your data
We use a small number of other companies to run Rauta ("sub-processors"). We do not sell your data, and we do not use it for advertising, to anyone.
- Vercel — hosts the website and the backend that stores your data.
- Resend — sends the transactional emails your account needs (sign-in links, account-related notices).
- Anthropic — generates AI session/weekly summaries when you use that feature (see above).
- Database host — [[TO BE CONFIRMED: which PostgreSQL hosting provider stores this data — not yet chosen]].
International transfers
Vercel, Resend, and Anthropic are US-based companies. Using them means your data can be transferred to, and processed in, the United States, outside the European Economic Area.
[[TO BE CONFIRMED: the specific transfer safeguard relied on for each sub-processor above (e.g. Standard Contractual Clauses, an adequacy decision) — to be confirmed against each provider's own data processing agreement]].
How long we keep it
We keep your account data for as long as your account is active. Rauta does not yet take payments, so none of the usual financial or tax record-keeping rules apply to your account today. If that changes (see the Terms of service on pricing), this section will be updated to describe what financial records are kept separately and for how long, under their own legal basis — everything else will still be deleted the way it is described below. The one existing exception, unrelated to payments, is the email suppression record described above.
Sign-in records are the one part of your account that is not kept for as long as your account is active: the hashed code or link and the IP address described under "Account information" above become eligible for deletion 30 days after they were created, and a daily automated process then permanently deletes them — so they are fully gone within 31 days of creation — on a fixed schedule, regardless of whether you're still signed up.
Deleting your account
Deleting your account is a genuine, permanent erasure — not a deactivation and not an "anonymise and keep the numbers" compromise. It's a two-step process: you request deletion while signed in, then confirm it via a link we email to your own address (the same mechanism as signing in, used here to make sure it's really you before something irreversible happens).
The moment you confirm, in one step: every session you had signed in on, anywhere, is signed out immediately, and your account row — together with every row of training history, logged sets, benchmark results, and programme enrollment tied to it — is permanently deleted. Nothing from that list is kept, aggregated, or re-identifiable afterward. The one exception is the bounce/spam-complaint suppression record described above, if one exists for your address — it survives independently of your account, for the reason given there.
You can sign up again afterward with the same email address, as a genuinely new account with no trace of the old one.
How to request deletion: [[TO BE CONFIRMED: the exact in-app path or URL for account deletion, once that screen exists — until then, request it by contacting us (see Contact below)]].
Your rights
Under GDPR, you can ask us to:
- let you access the personal data we hold about you
- correct it, if it's wrong
- erase it (see "Deleting your account" above)
- give you a copy of it in a portable format
- restrict or object to some kinds of processing
- withdraw consent for the health-adjacent fields, at any time
To exercise any of these, contact us at [[TO BE CONFIRMED: the contact email or in-app path for privacy/rights requests]].
You also have the right to lodge a complaint with your national data protection authority. [[TO BE CONFIRMED: which supervisory authority applies, once the controller's country of establishment (see 'Who we are' above) is settled]].
Age requirement
Rauta is not directed at children. Minimum age to create an account: [[TO BE CONFIRMED: minimum age policy — e.g. 16 (GDPR's own default) or 18 — an operator/legal decision, not made in this draft]].
Changes to this policy
If we change what we collect or why, we'll update this page and the "last updated" date above. If a change affects the health-adjacent consent described above, we'll ask you to confirm it again rather than carry your old answer forward silently.
Contact
Questions about this policy, or a request under "Your rights" above: [[TO BE CONFIRMED: the privacy/rights-request contact email address]].